| Previous | Next |
| ERROR_DS_NCNAME_MISSING_CR_REF | ERROR_DS_SCHEMA_NOT_LOADED |
ERROR_DS_SECURITY_CHECKING_ERROR
A security checking error has occurred.
Windows assigns decimal 8413 and hexadecimal 0x000020DD to ERROR_DS_SECURITY_CHECKING_ERROR. For ERROR_DS_SECURITY_CHECKING_ERROR, the decisive subject is an internal Active Directory security evaluation; the value alone does not reveal which object, server, file, session, or transition failed.
The native value for ERROR_DS_SECURITY_CHECKING_ERROR is 8413 (0x000020DD). Preserve ERROR_DS_SECURITY_CHECKING_ERROR immediately after the failing Windows call because later logging, cleanup, LDAP, RPC, or file operations can replace the last-error value.
Where this result appears
- For
ERROR_DS_SECURITY_CHECKING_ERROR, processing an internal Active Directory security evaluation. - For
ERROR_DS_SECURITY_CHECKING_ERROR, executing an LDAP, RPC, deployment, replication, or directory-management operation. - For
ERROR_DS_SECURITY_CHECKING_ERROR, working against a specific domain controller whose replica and schema state affect the result. - For
ERROR_DS_SECURITY_CHECKING_ERROR, translating extended directory diagnostics into a Win32 error for an application or administration tool.
State boundary to prove
ERROR_DS_SECURITY_CHECKING_ERROR applies to an internal Active Directory security evaluation and does not by itself prove that the entire server, directory, disk, session, or application is unavailable. The state boundary to prove for ERROR_DS_SECURITY_CHECKING_ERROR is whether the directory can build the security context and evaluate the requested access check reliably. Use object DN and security descriptor, caller SID and token groups, and requested access mask as independent evidence. When evidence for ERROR_DS_SECURITY_CHECKING_ERROR disagrees, preserve timestamps and investigate the transition instead of selecting the most convenient value.
Likely causes
- For
ERROR_DS_SECURITY_CHECKING_ERROR, the security descriptor is malformed or inaccessible. - For
ERROR_DS_SECURITY_CHECKING_ERROR, token or authorization data could not be evaluated. - For
ERROR_DS_SECURITY_CHECKING_ERROR, a directory security subsystem failed. - For
ERROR_DS_SECURITY_CHECKING_ERROR, replication left inconsistent security metadata.
Diagnostic sequence
- For
ERROR_DS_SECURITY_CHECKING_ERROR, capture error 8413 immediately at the API boundary and record the operation that was attempted. - For
ERROR_DS_SECURITY_CHECKING_ERROR, identify the exact owner of an internal Active Directory security evaluation, including object generation, server, path, session, replica, or client context. - For
ERROR_DS_SECURITY_CHECKING_ERROR, collect object DN and security descriptor before restarting a service or changing configuration. - For
ERROR_DS_SECURITY_CHECKING_ERROR, compare caller SID and token groups with the documented or observed precondition. - For
ERROR_DS_SECURITY_CHECKING_ERROR, correlate requested access mask with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace. - For
ERROR_DS_SECURITY_CHECKING_ERROR, determine whether side effects occurred and verify recovery after changing one responsible condition.
Evidence to collect
- For
ERROR_DS_SECURITY_CHECKING_ERROR, object DN and security descriptor. - For
ERROR_DS_SECURITY_CHECKING_ERROR, caller SID and token groups. - For
ERROR_DS_SECURITY_CHECKING_ERROR, requested access mask. - For
ERROR_DS_SECURITY_CHECKING_ERROR, Directory Service and security audit events.
Correlate ERROR_DS_SECURITY_CHECKING_ERROR with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace. Keep the first detailed status even when a later wrapper translates it to error 8413; the first status often distinguishes transport, authorization, storage, schema, state, and application-integrity causes that share the same final Win32 result.
Handling, retry, and recovery
For ERROR_DS_SECURITY_CHECKING_ERROR, the recovery objective is to preserve the failing descriptor and token context, validate directory and security metadata, and repair the specific object or subsystem rather than granting broader rights.
Retry ERROR_DS_SECURITY_CHECKING_ERROR only after the recorded condition changes and completion state is known. For ERROR_DS_SECURITY_CHECKING_ERROR, idempotent queries may be repeated after recovery, but mutations require a state check first; backoff cannot repair malformed input, corruption, missing structure, or policy rejection.
Telemetry and support fields
- For
ERROR_DS_SECURITY_CHECKING_ERROR, recordds_security_checking_error_apifor the producing function or management operation. - For
ERROR_DS_SECURITY_CHECKING_ERROR, recordds_security_checking_error_targetfor the file, log, session, replica, object, or server identity. - For
ERROR_DS_SECURITY_CHECKING_ERROR, recordds_security_checking_error_state_beforeandds_security_checking_error_requested_transition. - For
ERROR_DS_SECURITY_CHECKING_ERROR, recordds_security_checking_error_first_statusfor the earliest lower-level diagnostic.
For support escalation involving ERROR_DS_SECURITY_CHECKING_ERROR, retain decimal 8413, hexadecimal 0x000020DD, the API, UTC time, target identity, and first subsystem-specific status. For ERROR_DS_SECURITY_CHECKING_ERROR, include the smallest reproducible request and evidence that distinguishes this condition from nearby codes. In the context of ERROR_DS_SECURITY_CHECKING_ERROR, many ds codes are internal or management-facing and are not tied to one public function. the producing ldap, rpc, deployment, or management api must therefore be recorded with the code.
Difference from nearby results
For ERROR_DS_SECURITY_CHECKING_ERROR, ERROR_DS_SECURITY_ILLEGAL_MODIFY is a deliberate policy rejection; this code means the security check itself could not complete correctly
Practical validation scenario
One object consistently triggers the error while peers do not. Exporting its descriptor reveals invalid inherited data, and restoring a valid descriptor permits normal evaluation. The negative test should preserve the responsible condition and reproduce ERROR_DS_SECURITY_CHECKING_ERROR; the recovery test should change only the identified cause, repeat the same operation, and verify both success and the absence of an unintended partial side effect.
Developer and administrator guidance
Administrators handling ERROR_DS_SECURITY_CHECKING_ERROR should preserve Directory Service events, replication metadata, and the contacted domain controller before changing objects or forcing role transitions. For ERROR_DS_SECURITY_CHECKING_ERROR, developers should retain LDAP extended diagnostics and object identities across wrappers so the Win32 code does not erase the actionable directory result. Code that exposes ERROR_DS_SECURITY_CHECKING_ERROR through RPC, JSON, REST, PowerShell, or another protocol should preserve the Win32 domain, decimal 8413, hexadecimal 0x000020DD, and original component diagnostic.
References
- Microsoft: Win32 system error range containing this code — official context relevant to
ERROR_DS_SECURITY_CHECKING_ERROR. - Microsoft: AD DS troubleshooting — official context relevant to
ERROR_DS_SECURITY_CHECKING_ERROR. - Microsoft: repadmin — official context relevant to
ERROR_DS_SECURITY_CHECKING_ERROR. - Microsoft: dcdiag — official context relevant to
ERROR_DS_SECURITY_CHECKING_ERROR. - Microsoft: AD and LDS diagnostic event logging — official context relevant to
ERROR_DS_SECURITY_CHECKING_ERROR.
Looking for a different code? Search another status or error code.